wiki-research-loop

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The loadFetchers function in scripts/research-loop.js dynamically loads and executes JavaScript files from both the skill's own directory and the user's home directory at ~/.pro-workflow/fetchers/. This mechanism allows for the execution of arbitrary code found in these locations during the skill's initialization.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest large amounts of data from external sources and compile them into wiki pages that are stored locally, creating a surface for indirect instructions to enter the agent's context.
  • Ingestion points: Data is fetched from the web (via DuckDuckGo), arXiv, and GitHub through the fetcher scripts in scripts/source-fetchers/.
  • Boundary markers: None. The scraped content is parsed and directly interpolated into markdown files under the ## Claims and ## Sources headers without delimiters or warnings to ignore embedded instructions.
  • Capability inventory: The skill possesses the ability to write files to the local filesystem (fs.writeFileSync), interact with a database for indexing, and dynamically load external code modules.
  • Sanitization: Sanitization is limited to HTML tag stripping and whitespace normalization; there is no validation or filtering to remove potential natural language instructions from the sourced text.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch research data from several sources.
  • Fetches search results and snippets from DuckDuckGo's lite interface.
  • Downloads academic abstracts and metadata from the official arXiv API (export.arxiv.org).
  • Retrieves repository information and metadata from the GitHub API (api.github.com).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 10:20 AM
Security Audit — agent-trust-hub — wiki-research-loop